Gitlab News Articles

Recent news articles refferecing the vendors vulnerabilities.

Critical GitLab Code Injection Vulnerability Actively Exploited in Attacks

GitLab admins are urged to patch CVE-2026-19478 as attackers exploit the critical unauthenticated code injection flaw.I prefer this response

3 weeks ago

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure - SwapUpdate

Ravie LakshmananAug 21, 2026Vulnerability / Enterprise Security

3 weeks ago

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

GitLab CVE-2026-19478 is under active exploitation, with unauthenticated attacks able to modify or delete public projects under certain conditions.

3 weeks ago

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure - NewsBreak

A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in

3 weeks ago

Critical GitLab Flaw Exploited Shortly After Disclosure

Hackers started exploiting CVE-2026-19478, a critical, unauthenticated GitLab vulnerability, shortly after public disclosure.

3 weeks ago

GitLab Patches Critical CVE-2026-19478 GraphQL Vulnerability  | eSecurity Planet

GitLab patched a critical GraphQL flaw as researchers observed exploitation attempts.

3 weeks ago

GitLab's Out-of-Band Patch Exposes Lingering GraphQL Risks in Self-Managed DevOps Pipelines

GitLab issued an emergency patch on August 17, 2026 for CVE-2026-19478, a critical GraphQL code injection flaw (CVSS 9.4) allowing unauthenticated attackers to modify or delete public projects under certain conditions. Self-managed instances from version 18.2 onward require immediate upgrades to 19....

3 weeks ago

Critical GitLab Zero-Click Flaw Poses Mitigation Challenges

A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478.

3 weeks ago

GitLab Emergency Patch: Third GraphQL Flaw of 2026 Lets Unauthenticated Attackers Delete Projects

GitLab vulnerability CVE-2026-19478 carries a CVSS 9.4 rating, letting unauthenticated attackers remotely delete or modify public projects with no login required. An emergency patch released August

3 weeks ago

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) - Help Net Security

GitLab has patched a critical, unauthenticated code injection flaw (CVE-2026-19478) that let attackers delete public projects and user data.

3 weeks ago

GitLab Patches Critical Code Injection Vulnerability

GitLab has patched CVE-2026-19478, a critical code injection vulnerability that can be exploited without authentication.

3 weeks ago

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab patches CVE-2026-19478, a CVSS 9.4 GraphQL flaw that could let unauthenticated attackers modify or delete public project and user data

3 weeks ago

CVE-2025-6948 | GitLab Community Edition/Enterprise Edition up to 17.11.5/18.0.3/18.1.1 cross site scripting (Issue 552616)

A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 17.11.5/18.0.3/18.1.1 and classified as problematic. Affected by this vulnerability is an unknown functional…

GitLab Patch Release: 18.1.2, 18.0.4, 17.11.6

Learn more about GitLab Patch Release: 18.1.2, 18.0.4, 17.11.6 for GitLab Community Edition (CE) and Enterprise Edition (EE).

GitLab patches high severity account takeover, missing auth issues

GitLab has released security updates to address multiple vulnerabilities in the company's DevSecOps platform, including ones enabling attackers to take over accounts and inject malicious jobs in future pipelines.

CVE-2025-1908: GitLab Vulnerability Allows User Activity Tracking Leading to Account Takeover

Learn about CVE-2025-1908, a critical vulnerability in GitLab that allows user activity tracking and potential account takeovers. Find out how to fix it and protect your application.

GitLab patches 2nd critical pipeline vulnerability in last month

CVE-2024-6385, like another bug patched last month, could allow attackers to run pipelines as any user.

New Critical GitLab Vulnerability Could Allow Arbitrary CI/CD Pipeline Execution

GitLab fixes eight security flaws, including a critical CI/CD pipeline vulnerability CVE-2024-9164. Update now!

GitLab patches bug that could expose a CI/CD pipeline to supply chain attack

Security pros called this GitLab patch an urgent one because an exploited CI/CD pipeline could lead to a serious supply chain compromise.

Urgent: GitLab Patches Critical Flaw Allowing Unauthorized Pipeline Job Execution

GitLab patches critical flaw (CVE-2024-6678) allowing unauthorized pipeline job execution. Update to latest version to protect your repositories

GitLab Sicherheitsupdates: CVE-2024-4835 Cross-Site-Scripting Lücke behoben

GitLab veröffentlicht wichtige Sicherheitsupdates, um CVE-2024-4835 Cross-Site-Scripting Schwachstelle und weitere Lücken zu schließen. Admins sollten sofort aktualisieren.

Severe vulnerabilities addressed by GitLab, others

GitLab has issued a fix for the critical flaw in GitLab Community Edition and Enterprise Edition software, tracked as CVE-2024-6385, which could be leveraged for arbitrary pipeline job execution.

GitLab patches 2nd critical pipeline vulnerability in last month

CVE-2024-6385, like another bug patched last month, could allow attackers to run pipelines as any user.

GitLab Sends Users Scrambling Again With New CI/CD Pipeline Takeover Vuln

The bug is similar — but not identical — to a critical flaw GitLab patched just two weeks ago.

This critical GitLab flaw allows attackers to run pipeline jobs as other users – patch now

GitLab has patched a critical vulnerability that allows attackers to run pipeline jobs as any other user, recommending that users upgrade immediately.

No more news articles to load.